Everything a security review would ask us — published.
Sub-processors, data residency, encryption posture, incident response, responsible disclosure and audit reports. If your review needs a document, request it from security@binaryaiq.com.
The facts most review packs open with.
Every third party that touches customer data — enumerated.
The current register is published below. Customers are notified before a new sub-processor is added. The full addendum, with contractual controls, is available in the DPA on request.
What happens if something goes wrong.
Continuous monitoring across authentication, data plane and infrastructure. Anomalies raise a security incident record within minutes.
Named incident commander, tenant impact assessment, forensic log capture. Scope is established before any external communication.
Affected customers receive a factual notification with scope, timeline and mitigation. For DPDP Section 8(6) events, we support the customer's notification to the Board and data principals inside the statutory window.
Reporting a vulnerability.
Send vulnerability reports to security@binaryaiq.com. Include a description, reproduction steps and impact. Encrypted mail is welcomed — request our public key in first contact.
We acknowledge within 2 business days, triage within 5 business days and remediate on a severity-based timeline. Coordinated disclosure is expected; researchers acting in good faith are not pursued.
Testing must not access other customers' data, disrupt service or use social engineering against staff. Automated scanners against production are not permitted.
